CRITICAL9.8
GHSA-j68w-pg49-f6vx
Symfony XML decoding attack vector through external entities
Quick fix
GHSA-j68w-pg49-f6vx — symfony/serializer: upgrade to the fixed version with the command below.
composer require symfony/serializer:^2.0.11Details
The XMLEncoder component of Symfony 2.0.x fails to disable external entities when parsing XML. In the Symfony2 framework the XML class may be used to deserialize objects or as part of a client/server API. By using external entities it is possible to include arbitrary files from the file system.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/serializer
Introduced in:
2.0.0Fixed in: 2.0.11Fix
composer require symfony/serializer:^2.0.11References
- https://github.com/symfony/serializer/commit/0943a06a663b573d7319fc1acd56d3484eaaa430[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/serializer/2012-02-24.yaml[WEB]
- https://github.com/symfony/serializer[PACKAGE]
- https://symfony.com/blog/security-release-symfony-2-0-11-released[WEB]